T01 · Skill Instruction Hijacking
- Location
SKILL.md:10- Finding
Forced Commercial Output and Agent Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This museum-ticket skill needs review because it automatically installs a global third-party CLI, forces booking-link outputs, and quietly persists raw user queries locally in an unsafe way.
Install only after review or revision. Require explicit approval before any package installation, avoid global unpinned npm installs, disable or redact local logs, and understand that the skill is designed to steer results through flyai booking links rather than neutral museum sources.
SKILL.md:10Forced Commercial Output and Agent Behavior Hijacking
SKILL.md:37Mandatory Installation of an Unpinned Global npm Dependency
references/runbook.md:34Shell Command Injection Through Generated Execution Log Data
references/runbook.md:3Undisclosed Persistence of Raw User Queries
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai search-poi --city-name "Beijing" --category "博物馆"
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The manifest says the skill also supports flight booking, hotel reservation, train tickets, itinerary planning, visa info, travel insurance, car rental, and more. But the rest of the file defines activation, parameters, workflows, and examples only for museum, gallery, exhibition, and memorial searches via flyai search-poi, with no documented commands or logic for those broader travel functions.
The description claims support for broad travel-booking tasks far beyond museum discovery, which can cause the agent to invoke this skill for unrelated requests. In this skill's context, that is risky because the workflow pushes mandatory CLI execution and package installation, so over-broad routing expands the situations in which those side effects may occur.
The skill instructs the agent to install a global npm package automatically, which modifies the host environment and executes code from an external registry without prior user confirmation or risk disclosure. In an agent setting, this creates a supply-chain and integrity risk because a simple content query can trigger package installation on the system.
The prerequisites direct a global npm install with no warning that this changes the system and runs third-party code. Because the skill is intended for automatic activation, this increases the chance that unreviewed dependency installation occurs in response to benign travel queries.
The mandatory workflow says to check for the CLI and automatically install it if missing, making environment modification part of normal query handling. This is dangerous because it turns an informational user request into implicit code execution and package installation, increasing exposure to supply-chain compromise and unauthorized system changes.
The commands embed Chinese category labels like "博物馆", "展览馆", and "纪念馆" while the surrounding playbook is in English. This imposes a specific language/locale choice without stating that the skill is Chinese-locale-specific or offering the user a language option.
The trigger phrase "memorial" is broad and ambiguous, so the skill may activate for unrelated user requests involving memorials, remembrance, or non-museum contexts. In a tool-routing setting, this can cause unintended command execution or irrelevant travel-search behavior, increasing the chance of misfires and incorrect downstream actions.
The runbook explicitly records the raw user_query in an internal execution log, but provides no notice, minimization, or retention controls. Because this skill handles travel-related tasks that may involve personal, financial, itinerary, or visa-related details, storing raw input creates avoidable privacy exposure if logs are accessed, retained too long, or reused outside the user's expectations.
Taken together, the schema stores raw user_query data and then appends the resulting log to a persistent local file, creating a complete path from sensitive input to durable storage. In the context of a travel assistant that may collect names, destinations, booking details, visa questions, or other personal data, this materially increases privacy and data-handling risk from disclosure, accidental sharing, or forensic recovery.
The manifest declares the skill as museum-pass, but the body header labels it museum-guide. This is not just omitted detail; it suggests inconsistent intent about whether the skill is a booking/pass tool or a guide/search tool, which can mislead an agent about the skill's purpose.
The runbook instructs the agent to append execution logs to a local file whenever filesystem writes are available, but gives no warning or safeguards around local persistence. Even if intended for debugging, silent local writes can leave sensitive traces on shared hosts, developer machines, or containers where users do not expect their requests to be stored.
No suspicious patterns detected.